Skip to content

chore: bump up all non-major dependencies - autoclosed#284

Merged
Saul-Mirone merged 1 commit into
mainfrom
renovate/all-minor-patch
May 12, 2026
Merged

chore: bump up all non-major dependencies - autoclosed#284
Saul-Mirone merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 21, 2026

This PR contains the following updates:

Package Change Age Confidence Type Update
@types/node (source) 24.12.224.12.4 age confidence dependencies patch
next (source) 16.2.416.2.6 age confidence dependencies patch
oxfmt (source) ^0.46.0^0.49.0 age confidence devDependencies minor
pnpm (source) 10.33.010.33.4 age confidence packageManager patch
pnpm/action-setup v6.0.1v6.0.7 age confidence action patch
react (source) 19.2.519.2.6 age confidence dependencies patch
react-dom (source) 19.2.519.2.6 age confidence dependencies patch

Release Notes

vercel/next.js (next)

v16.2.6

Compare Source

v16.2.5

Compare Source

oxc-project/oxc (oxfmt)

v0.49.0

Compare Source

🚀 Features

v0.48.0

Compare Source

v0.47.0

Compare Source

pnpm/pnpm (pnpm)

v10.33.4: pnpm 10.33.4

Compare Source

Patch Changes

  • Pin the integrity of git-hosted tarballs (codeload.github.com, gitlab.com, bitbucket.org) in the lockfile so that subsequent installs detect a tampered or substituted tarball and refuse to install it. Previously the lockfile only stored the tarball URL for git dependencies, so a compromised git host or a man-in-the-middle could serve arbitrary code on later installs without lockfile changes.

    A new gitHosted: true field is recorded on git-hosted tarball resolutions in the lockfile, letting every reader/writer route them by a single typed check instead of pattern-matching the tarball URL in each call site. Lockfiles written by older pnpm versions are enriched on load (URL fallback) so the field can be relied on uniformly across the codebase.

  • Fix a regression where pnpm --recursive --filter '!<pkg>' run/exec/test/add would include the workspace root in the matched projects. The workspace root is now correctly excluded by default when only negative --filter arguments are provided, matching the documented behavior. To include the root, pass --include-workspace-root #​11341.

Platinum Sponsors

Bit

Gold Sponsors

Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx

v10.33.3

Compare Source

v10.33.2

Compare Source

v10.33.1: pnpm 10.33.1

Compare Source

Patch Changes
  • When a project's packageManager field selects pnpm v11 or newer, commands that v10 would have passed through to npm (version, login, logout, publish, unpublish, deprecate, dist-tag, docs, ping, search, star, stars, unstar, whoami, etc.) are now handed over to the wanted pnpm, which implements them natively. Previously they silently shelled out to npm — making, for example, pnpm version --help print npm's help on a project with packageManager: pnpm@11.0.0-rc.3 #​11328.
Platinum Sponsors
Bit
Gold Sponsors
Sanity Discord Vite
SerpApi CodeRabbit Stackblitz
Workleap Nx
pnpm/action-setup (pnpm/action-setup)

v6.0.7

Compare Source

v6.0.6

Compare Source

What's Changed
  • fix: bin_dest output points to self-updated pnpm, not bootstrap by @​zkochan in #​249

Full Changelog: pnpm/action-setup@v6.0.5...v6.0.6

v6.0.5

Compare Source

What's Changed
  • fix: append (not prepend) action node dir to PATH for npm bootstrap by @​zkochan in #​241

Full Changelog: pnpm/action-setup@v6.0.4...v6.0.5

v6.0.4

Compare Source

What's Changed
New Contributors

Full Changelog: pnpm/action-setup@v6.0.3...v6.0.4

v6.0.3

Compare Source

Updated pnpm to v11.0.0-rc.5

Full Changelog: pnpm/action-setup@v6.0.2...v6.0.3

v6.0.2

Compare Source

What's Changed
New Contributors

Full Changelog: pnpm/action-setup@v6.0.1...v6.0.2

facebook/react (react)

v19.2.6: 19.2.6 (May 6th, 2026)

Compare Source

React Server Components


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 21, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
milkdown Ready Ready Preview, Comment May 12, 2026 1:40am

Request Review

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 21, 2026

⚠️ No Changeset found

Latest commit: 357204f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from b24d03e to e0a182f Compare April 22, 2026 15:40
@renovate renovate Bot changed the title chore: bump up pnpm/action-setup action to v6.0.3 chore: bump up all non-major dependencies Apr 22, 2026
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from e0a182f to a10077b Compare April 27, 2026 14:13
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from a10077b to bd82da7 Compare April 30, 2026 21:32
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from bd82da7 to 95f7f07 Compare May 2, 2026 21:33
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 95f7f07 to bcc56f5 Compare May 4, 2026 21:57
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from bcc56f5 to 6433aa2 Compare May 5, 2026 15:14
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 6433aa2 to ca88b9c Compare May 6, 2026 14:38
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from ca88b9c to c4b58da Compare May 6, 2026 17:37
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from c4b58da to f25452b Compare May 7, 2026 20:44
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from f25452b to e4b74c7 Compare May 8, 2026 04:38
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from e4b74c7 to f67988f Compare May 9, 2026 00:39
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from f67988f to 2699a56 Compare May 11, 2026 14:56
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 2699a56 to 3b7e772 Compare May 11, 2026 21:27
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch from 3b7e772 to 357204f Compare May 12, 2026 01:38
@Saul-Mirone Saul-Mirone merged commit 8ae4de7 into main May 12, 2026
6 checks passed
@Saul-Mirone Saul-Mirone deleted the renovate/all-minor-patch branch May 12, 2026 05:12
@renovate renovate Bot changed the title chore: bump up all non-major dependencies chore: bump up all non-major dependencies - autoclosed May 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant